From c6d4373f2e057be35e873014282bb1b00c7644ea Mon Sep 17 00:00:00 2001 From: zkldi <20380519+zkldi@users.noreply.github.com> Date: Sat, 23 Apr 2022 00:58:21 +0100 Subject: [PATCH] fix: make revert-import require delete_score perm --- .../server/router/api/v1/imports/router.ts | 28 +++++++++++++------ 1 file changed, 19 insertions(+), 9 deletions(-) diff --git a/server/src/server/router/api/v1/imports/router.ts b/server/src/server/router/api/v1/imports/router.ts index a24b55ff6..dd9f62552 100644 --- a/server/src/server/router/api/v1/imports/router.ts +++ b/server/src/server/router/api/v1/imports/router.ts @@ -5,6 +5,7 @@ import { RevertImport } from "lib/imports/imports"; import CreateLogCtx from "lib/logger/logger"; import ScoreImportQueue, { ScoreImportQueueEvents } from "lib/score-import/worker/queue"; import { ServerConfig, TachiConfig } from "lib/setup/config"; +import { RequirePermissions } from "server/middleware/auth"; import { GetRelevantSongsAndCharts } from "utils/db"; import { GetUserWithID } from "utils/user"; import { GetImportFromParam, RequireOwnershipOfImport } from "./middleware"; @@ -61,19 +62,28 @@ router.get("/:importID", GetImportFromParam, async (req, res) => { * * Must be a request from the owner of this import. * + * Counterintuitively, this endpoint requires the "delete_score" permission. This is + * because reverting an import is actually just deleting all of its scores. + * * @name POST /api/v1/imports/:importID/revert */ -router.post("/:importID/revert", GetImportFromParam, RequireOwnershipOfImport, async (req, res) => { - const importDoc = req[SYMBOL_TachiData]!.importDoc!; +router.post( + "/:importID/revert", + GetImportFromParam, + RequireOwnershipOfImport, + RequirePermissions("delete_score"), + async (req, res) => { + const importDoc = req[SYMBOL_TachiData]!.importDoc!; - await RevertImport(importDoc); + await RevertImport(importDoc); - return res.status(200).json({ - success: true, - description: `Reverted import.`, - body: {}, - }); -}); + return res.status(200).json({ + success: true, + description: `Reverted import.`, + body: {}, + }); + } +); // Finding jobs is slightly harder than just doing a key lookup, because of retrying. async function FindImportJob(importID: string) {